Definition
Disaster recovery is the technical and operational work of restoring critical systems, data, and services after disruption while protecting ePHI during the process.
In practice
- A restore exercise validates not just database recovery but keys, identities, integrations, and application configuration.
- A clinic maintains a downtime workflow for urgent care while systems recover.
Who this applies to
- Covered entities and business associates
- Infrastructure, clinical operations, and continuity leaders
- Cloud and backup providers supporting critical workloads
What the rule asks for
- Establish data backup, disaster recovery, and emergency mode operation procedures.
- Test and revise contingency plans as appropriate.
- Identify criticality, dependencies, recovery objectives, and responsible people.
How teams put it into practice
- Map dependencies and define what must work first during an outage.
- Test restoration from isolated backups and record actual recovery results.
- Include vendor outages, identity dependencies, and communications in exercises.
Common mistakes
- Calling a backup job a recovery plan.
- Never testing restores or emergency access.
- Ignoring the business process that must operate when the primary application is down.
Questions that come up
Does HIPAA specify an RTO or RPO?
HIPAA does not prescribe one universal recovery time or recovery point objective; organizations should set objectives based on risk, criticality, and operational needs.
References
- Contingency planning guidance HHS Office for Civil Rights
- NIST SP 800-34 National Institute of Standards and Technology